diff --git a/.github/scripts/packaging-check.sh b/.github/scripts/packaging-check.sh index caebb66870eb..2f5204aafc0b 100755 --- a/.github/scripts/packaging-check.sh +++ b/.github/scripts/packaging-check.sh @@ -20,14 +20,16 @@ set -x ./.github/scripts/setup_generate_license.sh # This job is the single place in CI that validates everything a release build -# produces: RAT license headers, javadoc and source jars, the binary and source -# distribution assemblies, and the license dependency reports. The apache-release -# profile is enabled here so that the Docker test job only needs to build the -# binary tarball. GPG signing and the OWASP dependency check are skipped as they -# are not meaningful in CI. -./mvnw -B clean install -Prat -Papache-release --fail-at-end \ +# produces: javadoc and source jars, the binary and source distribution +# assemblies, and the license dependency reports. The apache-release profile is +# enabled here so that the Docker test job only needs to build the binary +# tarball. GPG signing and the OWASP dependency check are skipped as they are not +# meaningful in CI. RAT is not run here: apache-rat-plugin is not safe to run in +# a parallel (-T) build, so the single-threaded RAT pass in static-checks-maven.sh +# covers it instead. +./mvnw -B clean install -Papache-release --fail-at-end \ -pl '!benchmarks, !distribution' -P skip-tests -Dweb.console.skip=false -T1C \ -Dgpg.skip -Ddependency-check.skip -./mvnw -B install -Prat -Papache-release -Pdist -Pbundle-contrib-exts --fail-at-end \ +./mvnw -B install -Papache-release -Pdist -Pbundle-contrib-exts --fail-at-end \ -pl 'distribution' -P skip-tests -Dweb.console.skip=false -T1C \ -Dgpg.skip -Ddependency-check.skip diff --git a/.github/scripts/static-checks-maven.sh b/.github/scripts/static-checks-maven.sh index adca96c10b07..b50e03dedeff 100755 --- a/.github/scripts/static-checks-maven.sh +++ b/.github/scripts/static-checks-maven.sh @@ -23,8 +23,9 @@ echo 'Running Maven install...' ./mvnw -B checkstyle:checkstyle --fail-at-end -# Repo-wide RAT check. packaging-check also runs RAT, but it excludes the -# benchmarks module from its reactor, so keep this standalone pass here. +# Repo-wide RAT check. This is the only RAT pass in CI. It must run without -T: +# apache-rat-plugin 0.17+ shares per-run state across modules, so parallel runs +# can drop configured excludes or throw NPEs (RAT-553, fixed upstream by RAT-573). ./mvnw -B apache-rat:check -Prat --fail-at-end \ -Dorg.slf4j.simpleLogger.log.org.apache.maven.cli.transfer.Slf4jMavenTransferListener=warn \ -Drat.consoleOutput=true